Re: Roaming profile and folder redirection

From: H. v.d. Bunte (HvdBunte_at_discussions.microsoft.com)
Date: 08/13/04


Date: Fri, 13 Aug 2004 05:45:05 -0700

How can i change the permissions so that the administrator can access every
file and folder?

Because the admin has full control everywhere.

Thanks a lot for youre help so far :)

H. v.d. Bunte

"Lanwench [MVP - Exchange]" wrote:

> H. v.d. Bunte wrote:
> > Hello,
> >
> > I have some problems with this subject.
> >
> > I'm using a W2k3 server and i would like use a roaming profile for my
> > users. I created 8 users with folder redirection and it worked
> > perfect. I didn't got any event errors.
> >
> > But now i'm making a roaming profile with a profilepath to
> > \\server01\users\%username% and when i logon with a user and i look
> > at my server as Administrator i have the following problems:
> >
> > 1. I cannot look in the user folder (I could with my folder
> > redirection) Access denied. And when i deleted the folder I can only
> > do that when I make the admin the owner of the folder.
> > 2. I have errors in my eventviewer that the structure of my security
> > descriptor is invalid. event ID 1000 and 102.
>
> I think two things are being conflated here - home directory/folder
> redirection, and roaming profiles.
> General notes: "users" is usually the parent home directory folder for each
> user - don't use it for profiles. I'd set up a hidden share called home$ or
> users$ Administrator & System should have full control, and each username
> folder should also allow the individual user "modify" permissions. Specify
> the home directory in each user's ADUC properties - drive letter h or
> whatever you want, and \\server\users$\%username%.
>
> For profiles, I would set up a hidden share called profiles$ - set up the
> NTFS permissions so that all users, admins, and system = full control. In
> each user's ADUC properties for profiles, specify
> \\server\profiles$\%username%. The permissions will be changed after the
> user logs in so that they have full control and lock everyone out (although
> this can be changed later).
>
> Then for your folder redirection, specify "a folder under the home
> directory" in your default domain policy. The roaming profile will be in one
> place (profiles$) and the home directory and My Documents will be under
> users$.
> >
> > I hope somebody could help.
>
>
>



Relevant Pages

  • RE: Roaming Profiles and Synchronization
    ... It seems you want to get some suggestions on offline caching and folder ... roaming profiles is different with folder redirections. ... Administrators: Full Control ...
    (microsoft.public.windows.server.sbs)
  • Re: Broke My Roaming Profiles -- how to fix?
    ... Adding Full Control did not change the symptom. ... > JT Lovell wrote: ... >> renamed the share to profiles$. ... >> read/write/modify permissions to the folder. ...
    (microsoft.public.windows.server.general)
  • Re: add user error
    ... A home folder could not be created for this user. ... User profiles go to a folder called User Profiles ... Administrators Full Control ... Domain Users: traverse folder, list folder, read attributes and extended ...
    (microsoft.public.windows.server.sbs)
  • Desktop redirection broken, cant revert
    ... profiles weren't copied properly, ... denied" when Administrator tried to browse the folder. ... Admins full control (this folder, subs and files) ...
    (microsoft.public.win2000.group_policy)
  • Re: Roaming Profile Trouble
    ... > (Do I give full control permissions to the Admin and User groups? ... > Am I supposed to take ownership of the shared folder with the Domain ...
    (microsoft.public.windows.server.general)

Loading